Notary Knowledge by Derrick Spruill

Data Privacy: Handling PI in a Post-GDPR USA

Derrick Spruill Season 9 Episode 433

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 22:12

In an era where personal data is more valuable than ever, understanding how to safeguard information is a critical skill for any modern professional. Today, Eddie Montes Travis and Marylyn Lee Trotter discuss the essential protocols for managing sensitive data in a landscape heavily influenced by global privacy standards. • PI Identifiers: It is vital to recognize what exactly constitutes Personally Identifiable Information so you can categorize and protect client data with precision. • Storage Security: Keeping physical and digital records in locked or encrypted environments is no longer optional; it is a requirement for maintaining professional trust. • Disposal Protocols: Learning the correct ways to permanently destroy data once it is no longer needed prevents identity theft and ensures long-term legal compliance. • Regulation Awareness: Staying current with how international laws like GDPR influence domestic rules helps you anticipate changes in local privacy mandates. Safeguarding the privacy of those you serve is the foundation of a successful and ethical business. By implementing these security measures, you demonstrate a high level of integrity and care for your clients. Please remember to subscribe and like the podcast to get more expert insights every week!

Show Notes:
• Identifying common types of Personally Identifiable Information (PII).
• Best practices for the physical and digital storage of sensitive records.
• Understanding the ripple effect of GDPR on United States privacy regulations.
• The importance of secure data destruction and document disposal.

Buy Becoming a Notary on Amazon

Notary Knowledge Reference Guide and Notary Bible on Amazon

Your Sunday Notary Reading:
Notary Public Foundation: Essential Guide to Core Duties, Ethics, and Commissioning on Amazon

Your Monday Notary Reading:
Notary Operational Excellence: Mastering Certificates, Journals, Ink, and Copy Certification on Amazon

Your Tuesday Notary Reading:
Notary Fraud Shield: Real-World Tactics, Red Flags, and Refusal Strategies on Amazon

Your Wednesday Notary Reading:
The Mobile Notary Blueprint: Launching and Managing Your On-Demand Business on Amazon

Your Thursday Notary Reading:
Notary Niche Navigator: Your Guide to Loan Signings, Apostilles, I-9s, and More on Amazon

Your Friday Notary Reading:
Notary Law & Liability: Understanding State Regulations, Insurance, and Avoiding UPL

Your Saturday Notary Reading:
The Future Notary: Mastering RON, eNotary, and Complex Scenarios on Amazon

Quick & Easy Solutions How to Increase Mobile Notary Business for More Success & Profit: with 37 Professional Tips on Amazon

Executive Producer Derrick Spruill
Writers Marylyn Lee Trotter and Eddie Montes Travis
Graphics & Illustrations by Eddie Montes Travis
Music by Thomas

Contact Derrick Spruill

Support the show

Facebook


Instagram


LinkedIn


X

SPEAKER_00

Ready to unlock your notary potential and boost your income? It's time to move beyond basic notarizations. In Notary, Niche Navigator by Derek Spruel, learn the most profitable specialized services, learn to master high-demand areas like loan signings, international apostles, and I 9 employment verifications. This essential guide offers new ideas to help you become the go to expert in your field. Grab your copy of Notary Niche Navigator by Derek Sprugal today and start building your empire.

SPEAKER_01

Welcome to Notary Knowledge. I am Marilyn. And I am Eddie. Somewhere in a local strip mall shipping store, or you know, maybe sitting in an unlocked desk drawer at a real estate office right now is a spiral-bound notebook.

SPEAKER_02

Yeah, just a regular cheap notebook.

SPEAKER_01

Exactly. And inside that notebook is your home address, your driver's license number, and quite possibly your actual physical thumbprint in Black Inc.

SPEAKER_02

Which is wild because depending on where that notebook is physically sitting, pretty much anyone could just walk in off the street and ask to see it.

SPEAKER_01

Right. I mean, we spend massive amounts of energy guarding our digital footprint. We track down invisible data brokers, we navigate complex privacy settings on our phones.

SPEAKER_02

But today we are exploring a massive analog blind spot that is just hiding in plain sight.

SPEAKER_01

It really is the ultimate collision between centuries-old fraud prevention and the modern data privacy era. We're looking at the institution of the notary public crashing head on into the tsunami of comprehensive data privacy laws reshaping the country.

SPEAKER_02

And we have a huge stack of sources today to back this up. We're talking state notary handbooks, government codes, and some really deep legal analyses of major state data privacy acts.

SPEAKER_01

Yeah, from the CPRA in California to the VCDPA in Virginia, the mission for this exploration is to really figure out how your most sensitive personal information is handled, stored, and protected in a world where a simple signature can expose your entire identity.

SPEAKER_02

It is a huge topic.

SPEAKER_01

Okay, let's unpack this, starting with the physical object at the center of the storm, the notary journal. But before we get into the details, let's pause for a quick commercial break. And while you are listening, make sure you check out the notary knowledge books by Derek Spruell to really level up your understanding of the industry.

SPEAKER_02

Aaron Powell All right, so looking at the journal itself, it seems incredibly mundane, right?

SPEAKER_01

Very mundane.

SPEAKER_02

It's usually just a ledger you can buy at any office supply store. But when you apply the lens of modern data privacy legislation to it, that physical book is a staggering repository of personally identifiable information.

SPEAKER_01

Because state laws mandate a really heavy logging process.

SPEAKER_02

Aaron Powell Exactly. We are talking dates, printed full names, current home addresses, and it gets more specific the serial numbers of driver's licenses or passports and their exact expiration dates.

SPEAKER_01

So every time you finalize a will, buy a house, or sign a power of attorney, you are basically handing over the core ingredients of your identity.

SPEAKER_02

Aaron Powell You are. And the sources outline requirements that go way beyond just written data.

SPEAKER_01

Aaron Powell Yeah. Like if you live in California, the government code mandates a right thumbprint for any document affecting real property. So things like a deed as well as powers of attorney.

SPEAKER_02

A literal thumbprint.

SPEAKER_01

Wait, so if I sign a deed, does the state supply the notary with like some kind of secure encrypted biometric scanner that sends the data straight to a government vault?

SPEAKER_02

No. And that is the glaring vulnerability at the heart of this whole thing. It is a literal ink pad.

SPEAKER_01

Oh wow. Just ink on paper.

SPEAKER_02

Yeah. You press your thumb onto the ink and you roll it onto the paper page of the ledger. We are talking about raw, unsecured biometric data just sitting in a physical book.

SPEAKER_01

That is terrifying.

SPEAKER_02

It is. And when we look at this through the framework of the California Privacy Rights Act and CPRA, that physical book is a goldmine of what the law officially classifies as sensitive personal information.

SPEAKER_01

Right, because the CPRA specifically elevated the protection of those exact data points, didn't it? Like biometrics and government ID numbers.

SPEAKER_02

It did. The CPRA created a whole-tiered system because lawmakers recognized that a driver's license number or a thumbprint isn't just a regular data point. It is the exact key needed for severe systemic identity theft.

SPEAKER_01

So these massive new privacy laws force corporations to build, you know, heavily encrypted digital fortresses around this exact type of data.

SPEAKER_02

Aaron Ross Powell Exactly. But the irony is that the very same data sits completely unencrypted in paper notebooks on desks across the country.

SPEAKER_01

Which honestly reminds me of an internet cookie cache, but in the physical world.

SPEAKER_02

Oh, that's a good way to look at it.

SPEAKER_01

Right. Like we worry endlessly about websites tracking our clicks and dropping cookies in our browsers. We clear our cache all the time, but we have a physical analog cache out in the real world containing our actual biometrics, home addresses, and ID numbers.

SPEAKER_02

And that vulnerability extends into the digital realm now, too, because of remote online notarization or on.

SPEAKER_01

Oh yeah.

SPEAKER_02

States like Virginia and Florida now require extensive electronic records for remote notaries.

SPEAKER_01

Just think about what an audio video recording of a notarial act actually entails. You are sitting in your living room, you are holding your physical ID up to a webcam, and you are reading legal oaths aloud.

SPEAKER_02

Which means that video file captures your facial biometrics, your voice print, a high-resolution image of your government ID, and a clear view of the inside of your private home.

SPEAKER_01

And Florida mandates that the entire unedited audio video recording be stored on a server for a decade.

SPEAKER_02

Ten years, which forces us to ask the most critical question in any data privacy discussion. Who actually has access to this treasure trove of sensitive information once it's collected?

SPEAKER_01

You would naturally assume, given the severity of the data we just outlined, that the rules for accessing a notary journal would be incredibly strict and universally standardized.

SPEAKER_02

You would think so.

SPEAKER_01

But the reality is a complete patchwork. It is literally a geographic lottery across the United States. According to Nevada's revised statutes, a notary's journal is open to public inspection without qualification.

SPEAKER_02

Meaning the barrier to entry is virtually nonexistent.

SPEAKER_01

None.

SPEAKER_02

A person can simply walk into an office, request the journal, and flip through the pages, just viewing the addresses and ID numbers of everyone who signed a document before them.

SPEAKER_01

That is just wild. But then you cross the border into Arizona and the legal philosophy flips to a dual approach.

SPEAKER_02

Yeah. Arizona's interesting. If an Arizona Notarial Act involves something confidential under state or federal law like attorney client privilege information, the notary is required to keep a separate confidential journal specifically for those non-public records.

SPEAKER_01

But for the standard public entries, anyone can still view them, right?

SPEAKER_02

Aaron Powell Right. Provided they submit a specific written request detailing the month, year, and the name of the person whose signature was notarized.

SPEAKER_01

Aaron Powell So Arizona puts up a slight administrative hurdle, but the data remains fundamentally public. The state operates on the premise that the public has a right to verify the transaction.

SPEAKER_02

Aaron Powell But then you look at states like California and Massachusetts, which swing the pendulum back toward privacy. Both of those states require the journal to be kept in a locked, secure location at all times when not in active use.

SPEAKER_01

Aaron Powell And California goes even further. They only allow line item requests. Aaron Powell Right.

SPEAKER_02

So a member of the public cannot just browse the book.

SPEAKER_01

Aaron Powell No, they have to request a specific line, and the notary provides only that line. The sources mention the National Notary Association even recommends a physical tool called a notary privacy guard.

SPEAKER_02

Oh yeah, I've seen those.

SPEAKER_01

It's literally just a piece of plastic with a viewing window cut out. The notary places it over the page to physically conceal the unrelated entries above and below yours. That way you can't memorize the passport number of the person who signed a mortgage an hour before you did.

SPEAKER_02

It's a low-tech solution to a very serious privacy issue.

SPEAKER_01

So think about what this means for you, the listener. If crossing state lines from Nevada to Arizona to California fundamentally changes whether your identity is treated as a public open book or a tightly guarded secret, does this system make any sense in our current digital age?

SPEAKER_02

What's fascinating here is the historical tension this patchwork reveals. We have to remember why notaries were created in the first place.

SPEAKER_01

Oh, yeah. To prevent fraud.

SPEAKER_02

Exactly. Their primary centuries-old function is transparency. They serve as impartial state-appointed witnesses. Historically, the best way to prove a transaction wasn't forged was to make the record of it entirely public. Sunlight was the best disinfectant.

SPEAKER_01

But modern society demands the exact opposite. We are so terrified of identity theft, so we demand absolute privacy. We are caught in this massive tug of war.

SPEAKER_02

We really are. The legal system needs the transparency to authenticate property transfers and wills, but citizens need the privacy to protect their livelihoods.

SPEAKER_01

And you can see this tension perfectly articulated in the New York regulations from our sources.

SPEAKER_02

Yes. New York recently mandated that keeping a journal is a standard of reasonable care. The regulations explicitly state it is not a discretionary choice. It is a vital requirement to protect both the public from fraud and the notary from false accusations.

SPEAKER_01

Because in a court of law, that journal is the definitive piece of evidence. So the very thing that makes you vulnerable, the detailed logging of your personally identifiable information, is the exact mechanism the legal system relies on to prove you are who you say you are.

SPEAKER_02

It is a structural catch-22.

SPEAKER_01

It really is. And before we get into how modern privacy laws are totally blowing up this catch-22, we are going to take a quick pause for a commercial break. But real quick, if you are finding this exploration valuable, please take a second to rate the show, subscribe, and share notary knowledge with others.

SPEAKER_02

So for decades, that tension between transparency and privacy just hummed along in the background. The risk was low because obtaining the information required physically traveling to a notary's office.

SPEAKER_01

Right. But the landscape shifted dramatically starting in 2023. We officially entered the era of the modern comprehensive data privacy law.

SPEAKER_02

Yeah, this patchwork of state notary rules wouldn't be such a crisis if it weren't for the massive wave of legislation that followed.

SPEAKER_01

It started heavily in California with the transition from the CCPA to the CPRA. And that wasn't just a minor update. It established an entirely new enforcement body, the California Privacy Protection Agency.

SPEAKER_02

A dedicated privacy police, basically.

SPEAKER_01

Exactly. And it gave consumers expanded rights, like the right to correct inaccurate data, but it rapidly expanded way beyond the West Coast.

SPEAKER_02

Virginia didn't just copy California, though. Their VCDPA took a slightly more business-friendly approach to how consumer data is defined and utilized. But it still drew a hard line around sensitive data.

SPEAKER_01

And then came Colorado, Connecticut, and Utah.

SPEAKER_02

And looking at the massive 2025 updates across our sources, the states are getting even more aggressive. Minnesota introduced a new right for consumers to contest the results of automated profiling.

SPEAKER_00

Wow.

SPEAKER_02

Yeah. And Connecticut and Montana heavily enhance protections for miners' data, outright banning targeted advertising for anyone under 18.

SPEAKER_01

Here's where it gets really interesting. Let's look at Maryland. They instituted incredibly strict data minimization standards.

SPEAKER_02

Which is a huge shift.

SPEAKER_01

It is. Data minimization means a company is legally obligated to hold only the absolute minimum amount of data required to complete a transaction and to discard it immediately after.

SPEAKER_02

But in the context of a notary, this creates a massive friction point.

SPEAKER_01

A huge one. Minimization dictates you keep almost nothing, but state notary laws demand you keep absolutely everything for years. It's like the country's trying to build a giant puzzle to replace the lack of a federal privacy law.

SPEAKER_02

Yeah, I like that analogy.

SPEAKER_01

Right. Every single state is cutting their own puzzle pieces in completely different shapes, and they absolutely do not fit together. It's creating a massive compliance headache for businesses.

SPEAKER_02

That visual captures the compliance nightmare perfectly. If we synthesize the core trend across all these states, the United States is largely adopting an opt-out model for general consumer data.

SPEAKER_01

Which differs significantly from Europe's GDPR, right?

SPEAKER_02

Right. Yes. GDPR operates on an opt-in model where a business must secure your explicit consent before collecting anything. In the US, a company can collect your browsing data by default, but you have the power to tell them to stop selling it or sharing it.

SPEAKER_01

Okay, I see.

SPEAKER_02

However, for sensitive data, which, as the sources explicitly outline, includes the biometric thumbprints and government ID numbers sitting in a notary journal, these new state laws heavily shift toward requiring prior consent.

SPEAKER_01

Or at the very least, giving consumers severe, strict control over how that specific data is used.

SPEAKER_02

Exactly. And this shift is monumental because it forces businesses to execute a process they have historically struggled with, which is data mapping.

SPEAKER_01

Because data mapping an offline system isn't like searching a cloud server for a keyword.

SPEAKER_02

None at all.

SPEAKER_01

It's like trying to index a massive library where none of the books have titles on the spines.

SPEAKER_02

Yeah.

SPEAKER_01

And the books themselves are scattered across thousands of independent contractors, home offices, and filing cabinets.

SPEAKER_02

And if a consumer exercises their right to say, show me all the sensitive data you hold on me, limit its use or delete it, a business is legally obligated to know where every single piece of that data lives.

SPEAKER_01

So for massive law firms, title companies, and banks, that means realizing their data footprint extends into physical storage rooms stacked with decades worth of notary journals.

SPEAKER_02

Because the privacy laws do not distinguish between a high-tech SQL database and a spiral notebook bought at a pharmacy when it comes to the definition of sensitive personal information.

SPEAKER_01

Which brings us to the ultimate legal collision in our discussion today. We have two massive legal frameworks hurtling toward each other. Head on. On one side, we have consumer privacy laws championing the right to delete. And on the other side, we have state notary laws mandating strict data retention.

SPEAKER_02

It is a direct, unavoidable conflict built right into the state codes.

SPEAKER_01

Let's look at the specifics. Privacy laws like California's Delete Act and the CPRA give you the power to approach a business and demand the permanent deletion of your personal information.

SPEAKER_02

And if the business fails to comply, they face massive financial penalties.

SPEAKER_01

But conversely, the notary handbooks show us that states are actually moving in the exact opposite direction. They are significantly increasing their mandatory data retention periods.

SPEAKER_02

Yes. Look at Texas. Under their recent Senate Bill, 693, they just doubled their retention requirement for notarial records from five years to ten years.

SPEAKER_01

Ten years. And Florida requires all of those remote online notarization audio video backups to be maintained for a decade, too. Colorado also mandates ten years.

SPEAKER_02

And in California, the physical retention is even more extreme. When a notary resigns, retires, or passes away, they don't simply shred their journals.

SPEAKER_01

Right. By law, those journals must be physically delivered to the county clerk, making them permanent government records.

SPEAKER_02

Exactly.

SPEAKER_01

So hold on, let's play out a hypothetical scenario based on these sources. Let's say you invoke your rights under the CPRA. You send a formal request to the title company that handled your home purchase five years ago, instructing them to delete all of your sensitive file data.

SPEAKER_02

Okay. Pretty standard request nowadays.

SPEAKER_01

But that same title company notarized your mortgage. They literally possess your physical thumbprint and your driver's license number in a bound book in their archives. The privacy law commands them to delete it. The notary law commands them to keep it for 10 years or eventually surrender it to the government. Right. I can just force them to shred that specific page, right? How does a business actually resolve this paradox?

SPEAKER_02

Well, you would think a deletion request is absolute, but you actually cannot force them to shred it.

SPEAKER_01

Wait, really?

SPEAKER_02

Really. If we connect this to the bigger picture, it all comes down to the hierarchy of laws and the specific, carefully crafted exemptions written into these privacy acts.

SPEAKER_01

Okay, so the lawmakers saw this coming.

SPEAKER_02

Yeah. When state lawmakers draft these massive sweeping privacy bills, they are acutely aware that they cannot accidentally break the foundational legal and financial systems of the state. So laws like the CPRA contain structural carve-outs.

SPEAKER_01

Like a legal escape hatch built specifically for compliance departments.

SPEAKER_02

Exactly. The CPRA specifically dictates that a business is not required to comply with a consumer's deletion request if maintaining that personal information is necessary to comply with a distinct legal obligation.

SPEAKER_01

Oh wow. And the state notary code demanding a 10-year retention period is a rock solid, undeniable legal obligation.

SPEAKER_02

Yep. Furthermore, the privacy laws contain broad exemptions for retaining any data necessary to exercise or defend legal claims or to cooperate with civil, criminal, or regulatory inquiries.

SPEAKER_01

So it's heavily protected.

SPEAKER_02

Think about it. Therefore, the notary journal operates as the ultimate defense of a legal claim document.

SPEAKER_01

So my right to privacy basically hits a brick wall the moment a notary stamp hits the paper.

SPEAKER_02

Basically, yes. Your right to privacy effectively stops where the state's need for legal authenticity begins. Yeah. The legal system is essentially making a calculated trade-off.

SPEAKER_01

They are saying, yes, we want to empower you to protect your data from being sold to targeted advertisers or exploited by shady data brokers.

SPEAKER_02

But when it comes to the bedrock systems of property ownership, healthcare directives, and the judicial system, objective authenticity will always trump personal privacy.

SPEAKER_01

The title company will absolutely delete your email address from their marketing database to comply with your request. But that physical thumbprint and ID number in the notary journal is staying right where it is, entirely immune to the privacy law.

SPEAKER_02

It really is entirely immune.

SPEAKER_01

It puts the limits of these new, highly publicized privacy laws into stark perspective. You feel incredibly empowered navigating a website, clicking delete my data, or reject all cookies.

SPEAKER_02

So the deepest, most sensitive, unencrypted records of your life are legally immune to that click.

SPEAKER_01

It is a sobering realization when consumers understand that their offline data is entirely out of their control.

SPEAKER_02

It really is.

SPEAKER_01

So let's wrap this up and summarize the journey we've just been on through these sources. We started by identifying the physical vulnerability of a simple spiral notebook sitting on a public desk, a book containing raw thumbprints, home addresses, and ID numbers.

SPEAKER_02

Then we navigated the wild west of state access laws, where simply driving from Nevada to California completely changes whether your sensitive identity markers are a public open book or a tightly guarded secret requiring line item redaction.

SPEAKER_01

We tracked the massive escalating wave of data privacy acts sweeping across the country from 2023 to 2025. Laws that are forcing massive corporations to map every single piece of data they hold, whether it lives on a cloud server or in a dusty filing cabinet.

SPEAKER_02

And finally, we hit that incredible legal collision where your modern, hard-fought right to be forgotten is completely legally overridden by a centuries-old mandate to retain evidence of authenticity.

SPEAKER_01

For you listening, the relevance of this is crucial. We've been extensively trained over the last decade to be hyper-aware of our online hygiene. We clear our browser history, we use VPNs, we meticulously manage our cookie preferences.

SPEAKER_02

But we rarely give a second thought to the offline, deeply mundane transactions that make up our lives.

SPEAKER_01

Exactly. The next time you sit down at a closing table to sign a stack of real estate papers, or you visit a shipping store to notarize a car title transfer, you need to be just as intensely aware of what is happening to your physical data footprint.

SPEAKER_02

Because you are leaving a permanent, legally mandated, unencrypted trail of your most sensitive identity markers in the physical world, and you have virtually no legal power to erase it.

SPEAKER_01

Which leaves us with one final provocative thought to mull over, one that really builds on the implications of these state codes. We've talked extensively about California requiring physical right thumbprints for real estate deeds. Right. We've talked about states mandating these journals be retained for a decade, and crucially laws that require those journals to eventually be turned over to county clerks when notaries retire or pass away.

SPEAKER_02

And that requirement systematically consolidates millions of disparate records into centralized local government archives.

SPEAKER_01

Yes. So the ultimate question is this: if biometric data, like raw thumbprints, are being systematically captured in physical journals by hundreds of thousands of independent notaries, legally retained for decades, and eventually surrendered to county clerks.

SPEAKER_02

Are we unintentionally building a massive decentralized government biometric database without any explicit citizen consent?

SPEAKER_01

It's definitely something to think about the next time you press your thumb onto an ink pad. If you have questions about this topic or any other notary issues, email your questions to Derek at dereksprawl.com.

SPEAKER_02

We will try to answer as soon as possible at the end of our shows.

SPEAKER_01

This show is executive produced by Derek Sproul. Lead writer is Marilyn Lee Trotter. Graphics by Eddie Montez Travis. Music by Thomas Pynum.

SPEAKER_02

Produced by Magnificent Works Business Solutions.

SPEAKER_01

Don't just be listeners of the knowledge, be doers of the knowledge. This is notary knowledge. Until next time.

SPEAKER_00

Ready to unlock your notary potential and boost your income? It's time to move beyond basic notarizations. In notary, Niche Navigator by Derek's approval, learn the most profitable specialized services, learn to master high demand areas like loan signings, international apostles, and I nine employment verifications. This essential guide offers new ideas to help you become the gota expert in the field. Grab your copy of Notary, Nicht Navigator by Derek's approval today. And start building your empire.

SPEAKER_01

I'ma start a praise, when I call his name, he's showing up. Time to elevate going up. Tell me what